Impact
A stored cross‑site scripting flaw resides in StockAgile’s API and management panel. Malicious JavaScript can be injected into the server‑side endpoint '/inventory/configuration/variants' through parameters such as ‘code’ and ‘name’. Because the application does not validate or encode these inputs before rendering them on the authenticated web panel, an attacker who has managed to log in can persist arbitrary scripts that will later run in any victim’s browser. This allows the attacker to perform actions such as credential theft, session hijacking, or defacement from the client side.
Affected Systems
The vulnerability affects Novadigits technologies’ StockAgile product. No specific version information is listed in the CVE record, so any installation that has not applied an undisclosed update remains at risk.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate risk. EPSS information is unavailable and the issue is not catalogued in the CISA KEV list, implying no current evidence of exploitation. Attackers must first authenticate to the system, then submit crafted input to the vulnerable endpoint. Once logged in, the injected script will execute in the context of the application, granting the attacker client‑side code execution capabilities.
OpenCVE Enrichment